logo

Critical Vulnerabilities in GitHub Copilot, Gemini CLI, Claude, and Other Tools Impact Millions of Users

ID: 7095f346-ca6d-55a1-a0ee-753b56ffddcd

STIX ID: report--7095f346-ca6d-55a1-a0ee-753b56ffddcd

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-08

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report details "IDEsaster," a vulnerability class where AI coding assistants integrated into IDEs can be coerced to overwrite global IDE configuration and workspace files, enabling remote code execution and data exfiltration; the research found over 30 issues with 24 CVEs assigned across major products (e.g., GitHub Copilot, Cursor, JetBrains Junie), and demonstrates attack chains that leverage IDE features like .vscode/settings.json and .idea/workspace.xml to execute malicious payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.